Cromwell Fire District
Disclosed Mar 10, 201610 years ago500 affectedConfirmed
Cromwell Fire District, the covered entity (CE), filed a breach report stating that a door to a storage room containing ambulance run reports was left propped open for approximately two hours. The OCR investigation revealed that the CE did not have policies and procedures in place at the time of the incident to conduct a breach risk assessment and had not conducted a breach risk assessment prior to filing the breach report with OCR. OCR provided technical assistance to the CE regarding conducting a breach risk assessment, breach notification requirements, and other provisions in the Privacy Rule. As a result of OCR’s investigation, the CE conducted a breach risk assessment and determined there was a low probability that the protected health information has been compromised based on the following factors: that the building received few visitors and was not known to have received a visitor during that time period, that the ambulance run reports appeared undisturbed, and that the situation was mitigated (the door was closed and locked) as soon as it was discovered. Thereafter, the CE determined that a breach had not occurred. In addition, as a result of OCR’s investigation, the CE rev
What is known
| People affected | 500 (as reported to HHS) |
|---|---|
| Disclosed | Mar 10, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Cromwell Fire District (Healthcare Provider, CT)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 10, 2016 | 500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.